D
David W. Hodgins
I haven't seen this one before.
Attached file message.zip removed from posting.
The attached zip file containes message.html.
It contains a upx compressed copy of what
kaspersky's online scanner calls I-Worm.Mimail
I haven't found any additional info on this one
yet. Anyone else seen it yet?
F-prot (dos) and Avg, with current definitions
do not flag the file, even if stripped down to
just the executable, and uncompressed.
Regards, Dave Hodgins
------- Forwarded message -------
Return-Path: <[email protected]>
Received: from localhost ([170.252.3.3])
by fep01-mail.bloor.is.net.cable.rogers.com
(InterMail vM.5.01.05.12 201-253-122-126-112-20020820) with SMTP
id <20030801184057.LGAL268656.fep01-mail.bloor.is.net.cable.rogers.com@localhost>
for <[email protected]>; Fri, 1 Aug 2003 14:40:57 -0400
From: (e-mail address removed)
To: Dhodgin1661 <[email protected]>
Reply-To: (e-mail address removed)
X-Mailer: The Bat! (v1.61)
X-Priority: 2 (High)
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------13242FBA09D51DF"
Message-Id: <20030801184057.LGAL268656.fep01-mail.bloor.is.net.cable.rogers.com@localhost>
Date: Fri, 1 Aug 2003 14:41:14 -0400
X-Spam-Status: Yes, hits=7.8 required=5.0
tests=FORGED_MUA_THEBAT,NO_REAL_NAME,SUBJ_HAS_SPACES,
SUBJ_HAS_UNIQ_ID
version=2.55
X-Spam-Level: *******
X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp)
X-Spam-Report: This mail is probably spam. The original message has been attached
along with this report, so you can recognize or block similar unwanted
mail in future. See http://spamassassin.org/tag/ for more details.
Content preview: Hello there,
I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details. --- Best regards,
Administrator uspueiee [...] Content analysis details: (7.80 points, 5 required)
NO_REAL_NAME (1.0 points) From: does not include a real name
SUBJ_HAS_SPACES (1.4 points) Subject contains lots of white space
SUBJ_HAS_UNIQ_ID (1.1 points) Subject contains a unique ID
FORGED_MUA_THEBAT (4.3 points) Forged mail pretending to be from The Bat!
X-Spam-Flag: YES
Subject: *****SPAM***** your account uspueiee
------------13242FBA09D51DF
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Hello there,
I would like to inform you about important information regarding your
email address. This email address will be expiring.
Please read attachment for details.
---
Best regards, Administrator
uspueiee
------------13242FBA09D51DF
Content-Type: application/x-zip-compressed; name="message.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="message.zip"
Attached file message.zip removed from posting.
The attached zip file containes message.html.
It contains a upx compressed copy of what
kaspersky's online scanner calls I-Worm.Mimail
I haven't found any additional info on this one
yet. Anyone else seen it yet?
F-prot (dos) and Avg, with current definitions
do not flag the file, even if stripped down to
just the executable, and uncompressed.
Regards, Dave Hodgins
------- Forwarded message -------
Return-Path: <[email protected]>
Received: from localhost ([170.252.3.3])
by fep01-mail.bloor.is.net.cable.rogers.com
(InterMail vM.5.01.05.12 201-253-122-126-112-20020820) with SMTP
id <20030801184057.LGAL268656.fep01-mail.bloor.is.net.cable.rogers.com@localhost>
for <[email protected]>; Fri, 1 Aug 2003 14:40:57 -0400
From: (e-mail address removed)
To: Dhodgin1661 <[email protected]>
Reply-To: (e-mail address removed)
X-Mailer: The Bat! (v1.61)
X-Priority: 2 (High)
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------13242FBA09D51DF"
Message-Id: <20030801184057.LGAL268656.fep01-mail.bloor.is.net.cable.rogers.com@localhost>
Date: Fri, 1 Aug 2003 14:41:14 -0400
X-Spam-Status: Yes, hits=7.8 required=5.0
tests=FORGED_MUA_THEBAT,NO_REAL_NAME,SUBJ_HAS_SPACES,
SUBJ_HAS_UNIQ_ID
version=2.55
X-Spam-Level: *******
X-Spam-Checker-Version: SpamAssassin 2.55 (1.174.2.19-2003-05-19-exp)
X-Spam-Report: This mail is probably spam. The original message has been attached
along with this report, so you can recognize or block similar unwanted
mail in future. See http://spamassassin.org/tag/ for more details.
Content preview: Hello there,
I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details. --- Best regards,
Administrator uspueiee [...] Content analysis details: (7.80 points, 5 required)
NO_REAL_NAME (1.0 points) From: does not include a real name
SUBJ_HAS_SPACES (1.4 points) Subject contains lots of white space
SUBJ_HAS_UNIQ_ID (1.1 points) Subject contains a unique ID
FORGED_MUA_THEBAT (4.3 points) Forged mail pretending to be from The Bat!
X-Spam-Flag: YES
Subject: *****SPAM***** your account uspueiee
------------13242FBA09D51DF
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Hello there,
I would like to inform you about important information regarding your
email address. This email address will be expiring.
Please read attachment for details.
---
Best regards, Administrator
uspueiee
------------13242FBA09D51DF
Content-Type: application/x-zip-compressed; name="message.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="message.zip"